home *** CD-ROM | disk | FTP | other *** search
-
- Update report of Thunderbyte Anti-Virus utilities.
- Prefixes:
- '-' indicates a change that does not require user attention.
- '->' indicates a modification that requires user attention, such as a
- change in program invocation, etc.
-
-
- 8.03 Product update
- -------------------
-
- All versions:
-
- -> The file appnotes.txt contains important information about changes in
- the software.
-
- -> Added a remove all macros option when OLE2 macro virus found.
-
- -> Added a remove all macros option (non-stop) when OLE2 macro virus
- found.
-
- - The OLE2-engine, used to detect macroviruses, has been redesigned
- and optimized for speed.
-
- - Minor bugs are solved
-
-
- DOS version:
-
- -> Added a special switch 'em' which optionally removes ALL macro entries
- from ALL VBA3 OLE2 files.
-
-
- All Windows versions:
-
- -> Virus information on Macro viruses is implemented. Add the sequence
- 'WM/', 'W97M/', 'XM/' or 'X97M/' before each search. For example,
- if you want to look up Concept you should look for 'WM/Concept'.
-
- -> The security options dialog now has two extra buttons: 'Select all'
- and 'Unselect all'.
-
- - The header of the TbSetup dialog (eg. Name, Length, ...) is now
- placed correctly
-
- - The date/timestamp in the TbScan logfile now uses the format for the
- current locale if the operating systems supports different locales.
-
- - If a drive cannot be accessed while TbScan or TbSetup is running,
- you now have the possibility to abort the process, retry accessing
- the disk or to ignore this disk.
-
- - The TbLoad program has been revised. It uses another method of
- uncompressing files, and it now supports two update directories.
- One directory need always be present, the other directory
- does not need to be present all the time.
-
- - The TbLoad program can now generate a logfile with the updated files.
-
- - The TBAV Windows versions would not recognize some bootsector viruses
- (the kind that make a floppy unreadable). This bug has been fixed.
-
- - The text in the 'results' window of the TbScan dialog is now properly
- filled.
-
- - The userinterface now correctly displays filenames and virusnames
- with a '&' character in the name.
-
- - When a changed file is detected, the description of the heuristic
- flag 'C' is now correct.
-
- - If you select 'Repeat Scan', you can put the scanner the first time
- the 'repeat' dialog shows up into 'demo mode'. This option is meant
- for demonstration purposes.
-
- - Some small bug concerning the background scan option was fixed.
-
-
- Windows 3.x version:
-
- - Solved a bug concerning the validation option of TBScan. It crashed
- in an intermediate version of TBAV-W3x V8.02.
-
- - It is possible to prevent the message that appears when the TBAV
- File I/O Monitor VxD is not loaded, from being shown by using the
- new entry in the 'Options|TBAVW Configuration' dialog box.
-
-
- Windows 95 and Windows NT version:
-
- -> Windows 95 Only: We are pleased to annouce the enhanced File I/O
- Monitor. This file interception module is able to scan all files that
- enter your system. This provides maximum user protection! You have also
- the possibility to restrict access to non-authorized files (files that
- were not previously processed by TbSetup).
-
- -> We have implemented Scanning in archive files. For now, only ZIP files
- and Microsoft compressed files can be scanned. Click the 'Scan inside
- Archive' option in the 'Tbscan|Options' dialog to enable this option.
- Longfilenames are not yet supported by this new feature. We expect
- this to be implemented in a future version.
-
- -> TBAV for Windows 95 and Windows NT now support live internet update
- of the (macro-)virus definition file.
-
- - TBAV for Windows95/NT now restores the focus after a it detected that
- a new (network) drive was mapped to the system.
-
- - If you'd reboot your computer while a floppy disk was in the diskdrive
- and you didn't reply to the question whether or not this disk should
- be scanned for viruses, Windows 95 displayed a 'End process' dialog-
- box. This has been fixed.
-
- - If TBAV for Windows 95 was scanning some target, all other scan
- activities (such as file I/O) were stopped. This is now fixed by
- using the new TBAVW95 VxD.
-
-
-
- Viruses:
-
- - The next viruses had a change of name only:
-
- From: To:
- ================================================================
- DNA DNA.1206
- Gullich Gullich.A
- Sepultura Sepultura.A
- WM/Chaos.A WM/Temple.F
- WM/Chaos.B WM/Temple.G
- WM/DMV.D WM/Helper.I
-
- - The next viruses had the indicated changes:
-
- Name Changes
- ================================================================
- Bagoes New signature
- Barrotes.1310/1874 -> Decomplexed signature
- Barrotes.1310.A-H
- Barrotes.1874
-
- - Added trojan signatures:
-
- Death Troyan
- QB2CDUCK
-
- - Added bootsector signatures:
-
- Autumnal.3072 {mbr}
- Baboon
- Beavis.A
- Beavis.B
- Bleah
- Brr
- Chameleon
- Dodgy
- Eco
- Elkey
- Gullich.B
- Gullion
- Hippie
- KL2
- No Message
- Palma
- Secretary
- SeeYou
- Sepultura.B
- Survivor
- SVIN
- Tiddler
- Vision
- VLAD.HD35
-
- - Added file virus signatures:
-
- Aforia.656
- AIWeed.852
- Autumnal.3072
- Baba.276
- Babe.1584
- Baran.3294
- Baran.4968
- Beast.498
- Bill.2658
- CMOS.3622
- Cool.929
- Countdown.1300
- Countdown.1363
- Cowboy.2483
- Cryptor.2169
- Cryptor.2582/3728
- Emhaka.749
- Euri.564
- Flu.1160
- Glacier.1183
- Hasta.884
- HLLO.7360
- HLLP.3263
- HLLP.5850.A
- HLLP.5850.B
- HLLP.5850.C
- HLLP.5850.D
- HLLP.5850.E
- HLLP.5850.F
- HLLP.5850.G
- HLLP.5850.H
- HLLP.5850.I
- HLLP.5904
- Inferno.1800
- IVP.345
- IVP.814
- Jell.841
- June_8th.1919
- Kewl.471
- Khizhnjak.785
- Kode.145/147
- Liata.327/337
- Lipa.3207
- Liquid_Power.1016
- LMD.2000
- Lost_Love.853
- Memorial.7783 {1}
- Memorial.7783 {2}
- Monster_O.213
- Monster_O.217
- Monster_O.323
- Monster_O.327
- Mothership.655
- Noiembrie.610
- Novos.1000
- Odious.569
- Pamyat.2000
- Paulus.1804
- Phile.209
- Phile.210
- Prut.218
- Sailor.2048 {mbr}
- Sailor.2048
- Sailor.2048 {win}
- Selfex.1472
- Soupy.1073
- Spanska.4250
- Steatoda
- Stercor.818
- StoneHeart
- Sui.585
- Suxx.442
- TakeControl.4505
- Trivial.281.B
- Xavirus.284
- Xavirus.535
- Xed.2869
- Zany.225
-
-
- - Added WordMacro virus recognition, unique identification and
- removal for:
-
- WM/Alex.A:Tw
- WM/Alex.B:Tw
- WM/Alex.C:Tw
- WM/Alex.D:Tw
- WM/Alex.E:Tw
- WM/Alien.G
- WM/Anak.B
- WM/Anak.C
- WM/Archer.A
- WM/Archer.B
- WM/Appder.J
- WM/Bandung.AX
- WM/Bandung.AY
- WM/Bandung.AZ
- WM/Bandung.BA
- WM/Bandung.BB
- WM/Bandung.BC
- WM/Clock.J:De
- WM/Clock.K:De
- WM/Clock.L:De
- WM/Cap.I
- WM/Cap.K
- WM/Cap.M
- WM/Cap.X
- WM/Cap.Y
- WM/Cap.Z
- WM/Cap.AA
- WM/Cap.AB
- WM/Cap.AC
- WM/Cap.AD
- WM/Cap.AE
- WM/Cap.AF
- WM/Cap.AG
- WM/Cap.AH
- WM/Cap.AI
- WM/Cap.AJ
- WM/Cap.AK
- WM/Cap.AL
- WM/Cap.AM
- WM/Cap.AN
- WM/Cap.AO
- WM/Cap.AP
- WM/Cap.AQ
- WM/Cap.AR
- WM/Cap.AS
- WM/Cheat.A
- WM/Cheat.B
- WM/Colors.BO
- WM/Colors.BP
- WM/Colors.BQ
- WM/Concept.BB1
- WM/Concept.BE
- WM/Concept.BF
- WM/Concept.BG
- WM/Concept.BH
- WM/Concept.BI
- WM/Concept.BJ
- WM/Concept.BK
- WM/Concept.BK1
- WM/Concept.BL
- WM/Concept.BM
- WM/Concept.BN
- WM/CountTen.E
- WM/Dark.E
- WM/DMV.G
- WM/DMV.H
- WM/Divina.I
- WM/Divina.J
- WM/Dracula.B
- WM/Dzt.G
- WM/Emt.A
- WM/FormatS.A
- WM/Four.A
- WM/Friday.D:De
- WM/Friday.E:De
- WM/Gas.A
- WM/GoldSecret.B
- WM/GoldSecret.B
- WM/Goodnight.C
- WM/Goodnight.C1
- WM/Goodnight.C2
- WM/Goodnight.D
- WM/Goodnight.D1
- WM/Goodnight.D2
- WM/Goodnight.E
- WM/Goodnight.E1
- WM/Goodnight.E2
- WM/Header.A
- WM/Hiac.A
- WM/Hitman.A
- WM/Hunter.C:De
- WM/Hybrid.A1
- WM/Hybrid.I
- WM/Hybrid.J
- WM/Imposter.F
- WM/Incarnate.A1
- WM/India.A
- WM/Johnny.O
- WM/Johnny.O1
- WM/KillLuf.A
- WM/Lamah.A
- WM/Lox.B
- WM/Lunar.A.Dropper
- WM/Lunar.A
- WM/Makrone.B:De
- WM/MDMA.X
- WM/MDMA.Y
- WM/MDMA.Z
- WM/Mess.A
- WM/Minimal.Q
- WM/Minimal.R
- WM/Minimal.S
- WM/Minimal.T
- WM/Muck.I
- WM/Muck.J
- WM/Muck.K
- WM/Muck.L
- WM/Muck.M
- WM/Muck.N
- WM/Muck.O
- WM/Muck.P
- WM/Mulai.A
- WM/Niceday.N
- WM/Niknat.A
- WM/NoForce.A
- WM/Nop.M:De
- WM/Nop.N
- WM/NPad.CL
- WM/NPad.CM
- WM/NPad.CN
- WM/NPad.CO
- WM/NPad.CP
- WM/NPad.CQ
- WM/NPad.CR
- WM/NPad.CS
- WM/NPad.CT
- WM/NPad.CU
- WM/NPad.CV
- WM/NPad.CW
- WM/NPad.CX
- WM/NPad.CY
- WM/NPad.CZ
- WM/NPad.DA
- WM/NPad.DB
- WM/NPad.DC
- WM/NPad.DD
- WM/Nuclear.O
- WM/Nuclear.P
- WM/Nuclear.Q
- WM/Nuclear.R
- WM/Nuclear.S
- WM/Nuclear.T
- WM/Obay.A
- WM/Oblom.A
- WM/Oblom.B
- WM/Oblom.C
- WM/Oblom.D
- WM/Oblom.E
- WM/Paycheck.E
- WM/Paycheck.F
- WM/Paycheck.G
- WM/Rapi.AL2
- WM/Razer.A
- WM/Schumann.A
- WM/Schumann.B
- WM/Schumann.C
- WM/Screw.A
- WM/ShowOff.BV
- WM/ShowOff.BW
- WM/ShowOff.BX
- WM/ShowOff.BY
- WM/ShowOff.BZ
- WM/ShowOff.CA
- WM/ShowOff.CB
- WM/ShowOff.CC
- WM/ShowOff.CD
- WM/ShowOff.CE
- WM/ShowOff.CF
- WM/ShowOff.CG
- WM/Spooky.B:De
- WM/Spooky.C:De
- WM/Spy.A
- WM/Superstitious.A
- WM/Switcher.C
- WM/Switcher.D
- WM/Switcher.E
- WM/Switcher.F
- WM/SWLAB.G
- WM/Tear.B
- WM/Temple.C
- WM/Temple.D
- WM/Temple.E
- WM/Temple.E1
- WM/Temple.E2
- WM/Temple.H
- WM/Twno.AA:Tw
- WM/UgglyKid.A
- WM/Vampire.G:Tw
- WM/Vampire.H:Tw
- WM/Vampire.I:Tw
- WM/Vicinity.C:De
- WM/Vicis.A
- WM/Viva.A
- WM/Want.A:Tw
- WM/Wazzu.CK
- WM/Wazzu.CL
- WM/Wazzu.CM
- WM/Wazzu.CN
- WM/Wazzu.CO
- WM/Wazzu.CP
- WM/Wazzu.CQ
- WM/Wazzu.CR
- WM/Wazzu.CS
- WM/Wazzu.CT
- WM/Wazzu.CU
- WM/Wazzu.CV
-
- - Added ExcelMacro virus recognition, unique identification and
- removal for:
-
- XM/Delta.B
- XM/Don.A
- XM/Emperor.B
- XM/Hit.A
- XM/Hit.B
- XM/Hit.C
- XM/Hit.D
- XM/Laroux.F
- XM/Laroux.G
- XM/Laroux.H
- XM/Laroux.J
- XM/Team.A
-
- - Added WordMacro virus recognition and unique identification for:
-
- W97M/Alarm.A
- W97M/Box.D
- W97M/Chance.A
- W97M/Concept.BB
- W97M/DWMVCK1.A (dropper)
- W97M/MDMA.A
- W97M/Minimal.D
- W97M/Niceday.A
- W97M/Rapi.F2
- W97M/Rapi.AK2
- W97M/RatsAss.A
- W97M/Talon.J
- W97M/Talon.K
- W97M/Temple.A
- W97M/Twno.A:Tw
- W97M/Wazzu.AA
- W97M/Wazzu.AM
-
-